Re: Unofficial PEAR meeting summary

From: Date: Thu, 06 May 2004 20:34:33 +0000
Subject: Re: Unofficial PEAR meeting summary
References: 1 2 3 4 5 6 7 8  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-28908@lists.php.net to get a copy of this message
> On Thu May 06, 2004 at 02:3008PM -0500, Paul M Jones wrote: > > Is the PEAR credentials interface really in the open like that? Should > > we be passing credentials in the clear? Perhaps I am too paranoid... > Pear.php.net's authentication interface cannot be used via any sort of > network connection. And I don't think that this will change any time > soon. Martin. If you look at Auth/Container/PEAR.php, you'll see that the Auth package uses an RPC call to get userinfo. Within taht is the md5sum of the pass, which is compared to a locally md5'd password string. Wether this is by design, or a bug, in cases like this it's quite cool :) However, we are not passing anything in the open, except for perhaps and md5sum of the password. This could be considered secure by most people , unless you're really paranoid :) Cipri

« previous php.pear.dev (#28908) next »